Skip to content

What is new in NIST CSF 2.0

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · NIST CSF

CSF 2.0's headline is Govern — a sixth function that reframes cybersecurity from a technical checklist into an enterprise-risk discipline.

The big change: Govern

The headline of the 2024 CSF 2.0 update is a new sixth function — Govern — positioned as informing all the others. It covers organisational context, risk management strategy, roles and responsibilities, policy, oversight, and supply-chain risk. It reflects how cybersecurity has shifted from a technical checklist to an enterprise-risk discipline that boards engage with.

For everyone now

CSF 1.0 was framed for critical infrastructure. CSF 2.0 explicitly broadened the scope to organisations of all sizes and sectors, with guidance and quick-start material aimed at small businesses. The framework is now positioned as a general-purpose cybersecurity risk tool.

Supply chain elevated

Supply-chain cybersecurity risk management, which had grown in importance since 1.0, was strengthened and woven through the framework — most visibly within the new Govern function. It reflects the reality that most organisations' biggest risks now run through their vendors.

What to do about it

If you used CSF 1.1, the migration is mostly additive: add the governance layer (strategy, roles, oversight, supply chain) and re-map your profile to the new structure. SentinelPanda maps controls to the CSF 2.0 functions, Govern included.

NIST CSF 2.0 Govern function NIST CSF 2.0 core functions Managing third-party LLM and AI vendor risk

Run your compliance program in one workspace.